OT Security Engineer
Trans Bay Cable (Energy Infrastructure Subsidiary of NextEra Energy)
Own the firewall and remote-access boundary between corporate IT and the control environment for an HVDC transmission link.
- Own Check Point R81.20 firewall policy design and administration across PROD and T&D environments — three distributed deployments (dedicated management server with a two-gateway HA cluster) plus one standalone gateway/management deployment — covering 7 gateways and 250+ rules and RBAC policies.
- Designed and enforced Purdue Model segmentation across Levels 2–5 and the OT DMZ, isolating control networks from corporate and permitting only justified, least-privilege cross-boundary flows in alignment with NERC CIP-005 ESP requirements.
- Built and own the Interactive Remote Access (IRA) path into OT: users on the corporate VPN reach the DMZ, authenticate to Windows jump hosts (RDS) with a separate DMZ-domain account and RSA MFA, and RBAC-scoped Check Point rules govern onward access into the control network.
- Maintained NERC CIP-005 firewall rule governance by documenting business justifications and source references for each permitted rule, producing audit-ready evidence for compliance reviews.
- Managed Cisco Firepower (FMC) / ASA rulesets and Windows host-based firewall policy through Group Policy alongside Check Point to support segmentation within the Purdue architecture.
- Designed a secure remote-execution pathway between segmented networks using PowerShell Just Enough Administration (JEA), enabling controlled cross-boundary operations without weakening segmentation.
- Implemented automated, secure configuration backups for Check Point firewalls using SCP with key-based authentication to protect configuration integrity and enable rapid recovery.
- Configured firewall rules and Active Directory integration to support Dragos deployment, enabling passive OT-specific threat detection and monitoring across segmented control and DMZ networks.
- Hardened the ICS Active Directory environment by enforcing least-privilege Group Policy and restricting administrative access to critical control systems.
- Configured PRTG Network Monitor to deliver infrastructure availability alerts to HMI displays, giving operators real-time visibility into IT/OT dependencies such as Active Directory and core network services.
- Triaged SIEM alerts in Tripwire Log Center by correlating firewall, endpoint, and OT system logs to assess operational impact and validate or dismiss threats within ICS environments.
- Deployed Trend Micro Apex One across Windows-based endpoints in ICS and DMZ networks, enhancing endpoint visibility and malware protection within segmented OT environments.
- Performed vulnerability assessments and remediation on IT/OT devices and documented system baselines to support compliance.
- Led procurement and rollout of a centralized cyber asset inventory system, directed vendor interactions, and authored scopes of work for security projects.
- Led consolidation of 10+ server racks housing 200+ assets, upgrading power circuits from 20A to 30A to increase capacity and support future infrastructure growth.